Skip to content

Human risk program maturity

Human Risk Maturity Model

The Human Risk Matrix shows which behaviors create risk. This model shows how a security program matures against them, in five levels. A program starts with compliance training, then learns to manage behavior: it maps the threats it faces to the behaviors that drive them, trains on those behaviors, measures them, and drives risky behavior down over time. The last step is the hardest: finding the rare, high-fidelity signals of malicious intent hidden in the noise, where insider-threat and counter-intelligence work sits.

Not every organization can build the same capability. Each level lists what it looks like for a small business, a mid-size company, and an enterprise. Each size has a ceiling: small stops at Level 3, mid-size at Level 4, enterprise at Level 5. Above the ceiling, you transfer, outsource, or accept the risk.

  1. L1Compliance Awareness
  2. L2Just-in-Time Training
  3. L3Threat-Informed Risk Management
  4. L4Insider-Threat Detection
  5. L5Proactive Human Risk Program

The five levels

  1. Level 1

    Compliance Awareness

    Training is a box to check.

    A baseline program that delivers required security training to everyone on a set schedule, to satisfy compliance. It produces a trained workforce on paper and the completion records an audit needs. It does not change behavior or reduce real risk, and success is measured by who finished rather than what changed.

    Focus:
    Educate
    Signals:
    Training completion records.
    Tooling:
    Awareness or SAT platform, email filtering, antivirus, MFA.
    Blind spot:
    It tracks attendance, not risk. It cannot show whether anyone is safer.

    By size

    Small
    An off-the-shelf training tool with automatic enrollment, run part time by IT or an MSP.
    Mid-size
    A security team runs the program in an LMS and reports completion to risk or audit.
    Enterprise
    A dedicated team runs an enterprise LMS with audited completion and policy sign-off.

    Next. Deliver training in context when a risky action happens, and measure behavior.

  2. Level 2

    Just-in-Time Training

    Coach people at the moment of risk.

    The program moves from scheduled training to coaching at the point of risk. It detects risky actions as they happen and delivers targeted guidance and a corrective step in the moment. It delivers fewer everyday mistakes and faster correction, but does not yet build a lasting picture of each person's risk.

    Focus:
    Educate, Intervene
    Signals:
    Live triggers from email, DLP, the browser, and endpoints. Each is handled on its own.
    Tooling:
    Human-risk platform nudges, email security, DLP.
    Blind spot:
    It reacts, but it has no memory. It cannot tell a repeat offender from a one-off, or coach based on history.

    By size

    Small
    Built-in warnings from the tools already in use, plus a platform's in-the-moment tips.
    Mid-size
    Security sets up contextual prompts across email and DLP, each with a way to report.
    Enterprise
    The awareness team ties just-in-time coaching to the wider program and tunes it by role.

    Next. Map the threats you face to the behaviors that drive them, and measure those behaviors over time.

  3. Level 3

    Threat-Informed Risk Management

    Manage the behaviors that drive risk.

    The program manages human risk through behavior. It maps the threats and risks it faces to the behaviors that drive them, using the Human Risk Matrix, then trains on those behaviors, measures them, and indexes on their reduction over time. It delivers a clear view of which behaviors matter most and evidence that risky behavior is falling.

    Focus:
    Educate, Evaluate, Monitor
    Signals:
    Behavioral data from UEBA, DLP, identity, and access logs, mapped to the matrix, plus simulation results.
    Tooling:
    Human-risk platform, UEBA, DLP, phishing simulation.
    Counter-intel:
    Controlled testing begins here, a first overlap with counter-intelligence method.
    Blind spot:
    It sees single behaviors, not the pattern that signals intent. A determined insider hides in normal noise.

    By size

    Small(ceiling)
    One human-risk platform tracks behavior, maps it to the matrix, and assigns targeted training. The owner reviews a monthly dashboard. This is a small business's ceiling.
    Mid-size
    Security feeds UEBA, DLP, and identity logs into a matrix-mapped platform and runs simulations.
    Enterprise
    A human-risk team runs integrated telemetry, an ongoing simulation program, and standing controlled tests.

    Next. Move from reducing common risky behavior to finding the rare signal that points to malicious intent.

  4. Level 4

    Insider-Threat Detection

    Watch for intent, not just error.

    With everyday risky behavior measured and falling, the program shifts to finding the needle in the haystack: the rare, high-fidelity signals that point to malicious intent rather than a mistake. It correlates behavior across sources to surface deliberate acts such as data theft, sabotage, or disabling controls, and runs an insider-threat process to investigate and respond. It delivers detection of the few malicious actors hidden in the noise, using counter-intelligence method within security operations.

    Focus:
    Monitor, Intervene
    Signals:
    Correlated data from the SOC and identity, DLP, and endpoint tools, plus HR context.
    Tooling:
    SIEM, EDR, identity analytics, insider-threat case management.
    Counter-intel:
    Detection borrows counter-intelligence methods to spot a witting insider before they act.
    Blind spot:
    It works case by case. It does not yet deter or disrupt a deliberate threat, and it still trails the adversary.

    By size

    Mid-size(ceiling)
    Managed detection and platform alerts feed a small group from IT, HR, and legal. External investigators are on call. This is a mid-size company's ceiling.
    Enterprise
    A dedicated insider-threat team with its own analysts, monitoring, and case management.

    Next. Move from detection to investigation, disruption, and steady adaptation.

  5. Level 5

    Proactive Human Risk Program

    North star

    A program that learns and gets ahead of risk.

    A program that learns and improves. It runs continuous detection, response, and threat intelligence, and feeds every outcome back to re-tune controls and training. It investigates and disrupts deliberate insider threats rather than only detecting them. It delivers a defense that stays ahead of a changing threat, reached by few organizations.

    Focus:
    Educate, Evaluate, Monitor, Intervene
    Signals:
    Behavior, telemetry, threat intelligence, and incident outcomes, used to reset priorities continuously.
    Tooling:
    Detection and response, threat intel, automation, case management.
    Counter-intel:
    Operational counter-intelligence is one capability here, to investigate and disrupt recruitment.
    Blind spot:
    It needs resources and authority that only the largest organizations have.

    By size

    Enterprise
    Continuous detection and response, threat hunting, and automation, with a standing counter-intelligence capability for investigations and law-enforcement work.
Self-assessment

Where are you today?

Pick your organization size and answer the questions. We’ll show your level today and what to do next.

Organization size
  1. 1Is everyone assigned recurring security training, with completion tracked for compliance?

  2. 2Do risky actions trigger an in-the-moment warning or nudge for the user?

  3. 3Does a platform track behavior against the matrix and assign targeted training you review?

Where you are today

Not yet at Level 1

Do next, to reach Level 1: Establish Level 1 — Compliance Awareness.